Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,961 - 1,980 of 3,443 CVEs
CVE-2014-125112 CRITICAL - 9.8

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when t...

Vendor: MIYAGAWA
Product: Plack::Middleware::Session::Cookie
Published: Mar 26, 2026
Source: NVD
CVE-2026-4484 CRITICAL - 9.8

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for ...

Published: Mar 26, 2026
Source: NVD
CVE-2026-33942 CRITICAL - 9.8

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed_classes => true. An attacker who can control the ser...

Vendor: saloonphp
Product: saloon
Published: Mar 26, 2026
Source: NVD
CVE-2026-33701 CRITICAL - 9.8

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earli...

Vendor: maven
Product: io.opentelemetry.javaagent:opentelemetry-javaagent
Published: Mar 25, 2026
Source: GitHub
CVE-2025-70888 CRITICAL - 9.8

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

Published: Mar 25, 2026
Source: NVD
CVE-2026-33670 CRITICAL - 9.8

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33669 CRITICAL - 9.8

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33696 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted parameters as part of...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-33660 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n host and achieve remote code executio...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-32573 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.7.

Vendor: Nelio Software
Product: Nelio AB Testing
Published: Mar 25, 2026
Source: NVD
CVE-2026-32539 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects PublishPress Revisions: from n/a through <= 3.7.23.

Vendor: PublishPress
Product: PublishPress Revisions
Published: Mar 25, 2026
Source: NVD
CVE-2026-32536 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a through <= 2.08.

Vendor: halfdata
Product: Green Downloads
Published: Mar 25, 2026
Source: NVD
CVE-2026-32525 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.

Vendor: jetmonsters
Product: JetFormBuilder
Published: Mar 25, 2026
Source: NVD
CVE-2026-32524 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.

Vendor: Jordy Meow
Product: Photo Engine
Published: Mar 25, 2026
Source: NVD
CVE-2026-32523 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.

Vendor: denishua
Product: WPJAM Basic
Published: Mar 25, 2026
Source: NVD
CVE-2026-32520 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.

Vendor: Andrew Munro / AffiliateWP
Product: RewardsWP
Published: Mar 25, 2026
Source: NVD
CVE-2026-32519 CRITICAL - 9.0

Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.

Vendor: Bit Apps
Product: Bit SMTP
Published: Mar 25, 2026
Source: NVD
CVE-2026-32512 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.

Vendor: Edge-Themes
Product: Pelicula
Published: Mar 25, 2026
Source: NVD
CVE-2026-32502 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.

Vendor: Select-Themes
Product: Borgholm
Published: Mar 25, 2026
Source: NVD
CVE-2026-32499 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.

Vendor: QuantumCloud
Product: ChatBot
Published: Mar 25, 2026
Source: NVD